PatchSiren

Kubio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Kubio CVE published 2026-10-03

CVE-2026-88783

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, allowing unauthenticated users to store markup which the plugin's own script later executes in the browser of any visitor or administrator reviewing the still-unapproved submission. This vulnerability allows unauthenticated users to potentially execute malicious code, lea [truncated]

Review Kubio CVE published 2026-10-03

CVE-2026-88782

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.